crt.sh Matador

Tames slow crt.sh searches with retries, caching, and local rendering.

crt.sh Matador

The crt.sh Matador is a human-operated search helper for crt.sh — the public Certificate Transparency log search engine maintained by Sectigo. When crt.sh is slow or times out, the Matador retries automatically, caches successful responses server-side, and renders the result locally so you always get an answer.

Supported queries: domain names (example.com, %.example.com), SHA-256 fingerprints, certificate IDs, SPKI hashes, serial numbers, CA IDs, and most other crt.sh parameters — including asn1= and h= pages.

This tool generates results on demand for human visitors. It is not a data feed, a proxy, or a crawlable archive. Automated crawlers will receive the landing page only and will not trigger any outbound requests to crt.sh.

Common Request Builder
Manual Request
Supported query options
Quick input
example.com
Plain domain — wrapped in q= automatically
%.example.com
Wildcard domain (% matches any prefix)
https://crt.sh/…
Paste a full crt.sh URL; Matador strips it to the minimal query on submit
64-char hex
SHA-256 fingerprint — searched with q= so crt.sh resolves the exact certificate
param=value&…
Raw query string, same as a crt.sh URL's query part
Certificate lookup
id=
Certificate by crt.sh numeric ID
sha256=
Certificate by SHA-256 fingerprint (hex)
d=
Download PEM by crt.sh ID
serial=
Serial number (hex) — combine with caid=
Name / identity
q=
Domain, CN, or any identity; supports % wildcard
identity=
Exact SAN or CN match
Key / CA
caid=
All certificates from a CA (by CA ID)
spkisha256=
Subject public key SHA-256
ski=
Subject key identifier
aki=
Authority key identifier — too broad by itself; use a CA ID or the CCADB issued-certificates view
Certificate views
asn1=
ASN.1 structure — parsed and rendered locally
h=
Certificate hierarchy
Refinements
deduplicate=Y
Collapse duplicate names in results
exclude=expired
Exclude expired certificates
match=@
Require email address in SAN
sort=
Column to sort by
dir=v
Descending sort direction
group=icaid
Group results by issuer CA
output=json
Raw JSON (auto-applied for list queries)
opt=
Display options, e.g. nometadata, pkimetal
Full crt.sh URL paste
https://crt.sh/?id=2004533348
Becomes id=2004533348
https://crt.sh/?asn1=2004533348
Becomes asn1=2004533348
https://crt.sh/mozilla-onecrl
Becomes the Matador OneCRL fingerprint query
https://crt.sh/mozilla-onecrl?opt=nometadata
Becomes the Matador OneCRL fingerprint query
Special crt.sh pages via path=
path=/mozilla-onecrl
Mozilla OneCRL revocation list query
path=/ccadb-cert/owner/<id>
CCADB certificates by CA owner
path=/…
Any other crt.sh path

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action